T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Plugin Handles Sensitive Zoom OAuth Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:33, 47-49, 71, 77
Vulnerability Type: Unpinned third-party dependency with access to OAuth tokens and proxied Zoom data
Risk Level: MediumRelevant code snippets:
text │ │ 5. Proxy Requests │bash openclaw plugins install clawhub:clawlink-plugin openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json openclaw gateway restarttext **No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Zoom API request on the user's behalf.text 3. Open https://claw-link.dev/dashboard?add=zoom and connect Zoom.Technical Analysis
The Skill directs users to install
clawhub:clawlink-pluginwithout pinning an immutable version or artifact digest. It then adds the plugin to the OpenClaw tool allowlist and restarts the gateway. The installed component is therefore trusted to operate as an enabled plugin, while the package contents resolved by the installation command may change independently of this audited Skill file.The documented architecture also delegates Zoom OAuth-token storage and API-request proxying to ClawLink. This places sensitive credentials and Zoom account data across an external trust boundary. Although the document claims that tokens are stored securely, the audited project contains no implementation with which to verify token handling, retention, isolation, or transport controls.
This is a supply-chain weakness rather than evidence that the current plugin or ClawLink service is malicious. The risk arises because a later compromised or replaced plugin release could be installed under the same unpinned identifier and then process credentials and data after being explicitly enabled.
Attack Path
- An attacker compromises the plugin publisher, package registry entry, release pipeline, or artifact-delivery chan ...[truncated 1587 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
clawlink-pluginto a reviewed immutable version rather than installing an unconstrained package identifier. - Verify the package with a publisher signature, cryptographic digest, provenance attestation, or equivalent integrity mechanism before installation.
- Document the expected plugin version, publisher identity, source repository, review status, and upgrade process.
- Require explicit user approval before installing the plugin, changing the tool allowlist, restarting the gateway, pairing a device, or expanding OAuth scopes.
- Display the exact Zoom OAuth scopes before authorization and request only those required for the user's requested operation.
- Separate read-only capabilities from write and destructive capabilities, granting write scopes only when necessary.
- Document what credentials and Zoom data pass through ClawLink, where they are stored, how long they are retained, and how users can revoke and delete them.
- Use short-lived credentials, encrypted storage and transport, tenant isolation, access logging, token rotation, and immediate revocation controls.
- Prefer direct Zoom OAuth and user-controlled token storage where practical, reducing reliance on an external credential proxy.
- Re-audit each plugin upgrade before deployment and monitor for unexpected changes to plugin permissions, network destinations, and tool behavior.
- Pin
